Courseiva

212-89 · topic practice

Email Incidents practice questions

Practise Certified Incident Handler (212-89) Email Incidents practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Email Incidents

What the exam tests

What to know about Email Incidents

Email Incidents questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Email Incidents exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Email Incidents questions

20 questions · select your answer, then reveal the explanation

When DKIM signature verification fails, what is the most likely technical cause?

Question 2mediummultiple choice
Read the full Email Incidents explanation →

An organization uses Microsoft 365. Which feature should an admin use to globally remove a malicious phishing email from all user mailboxes?

When performing manual phishing triage, which action should an analyst perform first after identifying a suspicious URL in an email body?

Question 4mediummultiple choice
Read the full Email Incidents explanation →

You are analyzing an email with a suspicious attachment. You notice the file name is 'invoice.pdf.exe'. What does this indicate?

Question 5mediummultiple choice
Read the full Email Incidents explanation →

Which protocol is used in conjunction with SPF and DKIM to provide instructions to the receiver on how to handle emails that fail authentication?

While analyzing an email header, you observe an SPF 'softfail'. What does this imply?

An analyst receives a report of a phishing email. Which email header field is most reliable for verifying the path taken by the email through intermediate mail transfer agents?

An analyst is drafting an email to a user who reported a phishing attempt. What is the most important tone to maintain?

You are reviewing a suspicious macro in a Word document attachment. Which tool is best suited for static analysis of the macro code?

Question 10easymultiple choice
Read the full Email Incidents explanation →

What is the primary risk associated with 'Executive Spoofing' or BEC (Business Email Compromise)?

Question 11easymultiple choice
Read the full Email Incidents explanation →

When an email incident is resolved, why is it necessary to update the organization's blocklist?

Question 12hardmultiple choice
Read the full Email Incidents explanation →

An attacker uses a 'Homograph Attack' to spoof a domain. How does the analyst detect this?

Question 13mediummultiple choice
Read the full Email Incidents explanation →

If a phishing email bypassed the perimeter email gateway, what is the next logical step in the incident response process?

Question 14mediummultiple choice
Read the full Email Incidents explanation →

Which of the following is a symptom of an 'Email Forwarding Rule' attack?

Question 15mediummultiple choice
Read the full Email Incidents explanation →

If a user receives an email with an attachment that is a 'compressed password-protected file', why is this a red flag?

Question 16hardmultiple choice
Read the full Email Incidents explanation →

An analyst identifies that an email originated from an unauthorized IP address despite passing SPF. What is the most likely cause?

Question 17mediummultiple choice
Read the full Email Incidents explanation →

What is the purpose of 'Sandboxing' in email security?

Which THREE of the following are common indicators of a phishing email?

Question 19easymultiple choice
Read the full Email Incidents explanation →

Which action should be taken after an email incident is contained and the indicators are identified?

Question 20hardmultiple choice
Read the full Email Incidents explanation →

An email header contains 'X-Forefront-Antispam-Report'. What can an analyst determine from this?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Email Incidents sessions

Start a Email Incidents only practice session

Every question in these sessions is drawn from the Email Incidents domain — nothing else.

Related practice questions

Related 212-89 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 212-89 exam test about Email Incidents?
Email Incidents questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Email Incidents questions in a focused session?
Yes — the session launcher on this page draws every question from the Email Incidents domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 212-89 topics?
Use the topic links above to move to related areas, or go back to the 212-89 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 212-89 exam covers. They are not copied from any real exam or dump site.